Senior SOC Analyst
Senior SOC Analyst
Location: London
Working Pattern: 4 days onsite, 1 day remote
Hours: Monday-Friday, standard business hours (no shift work)
Overview
We are seeking an experienced Senior SOC Analyst to support a major cyber security transformation programme within a global enterprise environment.
This role is ideal for a senior, hands-on Security Operations professional who combines strong incident investigation and threat analysis skills with experience in detection engineering, operational process development, and stakeholder engagement.
Working as a key bridge between regional and global Security Operations teams, you will play a critical role in the globalisation of security monitoring capabilities, helping to onboard, validate, optimise, and operationalise detection content while ensuring analysts have effective procedures and playbooks in place.
Key Responsibilities
Detection Rule Globalisation
- Lead the onboarding of EMEA detection rules into the Global Security Operations Centre.
- Review and validate detection logic, thresholds, alert conditions and expected behaviours across SIEM platforms such as Microsoft Sentinel, Splunk, QRadar, ArcSight, Exabeam, and LogRhythm.
- Ensure accurate mapping of detection content to recognised threat frameworks, including MITRE ATT&CK.
- Identify detection gaps, duplicate content and optimisation opportunities through detection engineering, threat hunting, and alert tuning activities.
- Support standardisation of monitoring capabilities across global security teams covering EDR, XDR, cloud, identity, email, and network security telemetry.
SOP Development & Operationalisation
- Develop and maintain Standard Operating Procedures (SOPs) for Tier 1 and Tier 2 SOC teams.
- Create investigation workflows, triage processes and escalation procedures for security incidents across Microsoft Defender, CrowdStrike, Cortex XDR, SentinelOne, Carbon Black, Azure, AWS, and GCP environments.
- Define required enrichment data, threat intelligence inputs and decision-making criteria.
- Ensure procedures are practical, repeatable and aligned with global security operations.
- Develop analyst playbooks and support SOAR and automation initiatives using technologies such as Microsoft Sentinel Automation, Cortex XSOAR, Splunk SOAR, Tines, and Swimlane.
Threat Analysis & Detection Validation
- Validate the effectiveness of security detections through threat-focused analysis and threat hunting activities.
- Perform quality assurance reviews of detection rules and analyst handling processes.
- Review and simulate alert scenarios to confirm investigation workflows and expected outcomes.
- Analyse attacker tactics, techniques and procedures (TTPs) and ensure detection content remains aligned with emerging threats.
- Utilise KQL, SPL, SQL, log analysis, event correlation, and telemetry investigation to validate detection's and support investigations.
- Support continuous improvement of detection and response capabilities.
Stakeholder Management & Collaboration
- Work closely with Security Operations, Detection Engineering, Threat Intelligence, Incident Response, and Global SOC teams.
- Act as a bridge between regional and global security functions.
- Deliver knowledge transfer sessions and operational walkthroughs.
- Translate complex technical concepts, detection logic, threat activity, and investigation outcomes into clear, business-friendly language.
Documentation & Governance
- Maintain high-quality documentation of detection content and operational procedures.
- Ensure traceability between detection logic, threat mappings and analyst workflows.
- Support audit and compliance requirements through robust process documentation.
Essential Skills & Experience
- Minimum 4 years' experience as a Tier 2 SOC Analyst (or recent Tier 3 experience).
- Strong background in security incident investigation, threat analysis, and threat hunting.
- Experience reviewing, tuning and validating detection rules and security alerts within SIEM platforms such as Microsoft Sentinel, Splunk, QRadar, ArcSight, Exabeam, or LogRhythm.
- Experience working with Microsoft Defender XDR, Microsoft Defender for Endpoint, CrowdStrike Falcon, Cortex XDR, SentinelOne, Carbon Black, or similar EDR/XDR technologies.
- Proven experience creating SOPs, playbooks, SOAR workflows, or response procedures for SOC teams.
- Strong understanding of attacker tactics, techniques and procedures (TTPs).
- Experience mapping detections to recognised threat frameworks such as MITRE ATT&CK.
- Experience using KQL, SPL, SQL, or similar query languages for investigation, threat hunting, and alert validation.
- Ability to define escalation criteria and investigation workflows.
- Experience working across multiple security teams and stakeholder groups.
- Strong communication skills with the ability to mentor and guide junior analysts.
Desirable Experience
- Security transformation, SOC modernisation, or globalisation projects.
- Detection engineering experience.
- SOAR workflow, automation, or response procedure development.
- Quality assurance of SOC processes and detection content.
- Experience within financial services or highly regulated environments.
- Experience delivering analyst training and knowledge transfer sessions.
- Experience working within Azure, AWS, or GCP cloud environments.
- Experience with threat intelligence integration, detection use case development, and security monitoring strategy.
Qualifications
- Degree in Cyber Security, Information Security, Computer Science, or equivalent practical experience.
- Relevant security operations, incident response, or monitoring certifications.
- Industry certifications such as Security+, CySA+, GCIH, GCIA, CISSP, SC-200, SC-300, AZ-500, or equivalent are advantageous.
Ideal Candidate
The ideal candidate is a genuinely senior SOC professional, not simply a Detection Engineer or Tier 1 Analyst. You will have a broad Security Operations background covering incident investigation, threat analysis, detection engineering, playbook development, stakeholder management, and mentoring.
You will be comfortable operating between regional and global teams, driving consistency across security operations and helping shape how detection and response capabilities are delivered at scale.
This is an excellent opportunity for a senior SOC professional looking to influence a large-scale Security Operations transformation while remaining technically hands-on.
GCS is acting as an Employment Agency in relation to this vacancy.
Senior SOC Analyst
Other similar jobs
Popular job searches
Your next job
starts here.
JOB SPECIALISMS
LATEST JOBS
TOP SEARCHES
LOCATIONS
- IT Support & Infrastructure
- Project Management
- Engineering
- Data
- Network security consultant
- Software Development
- Controls & Automation
- DevOps
- BI & Data Analytics
- Manufacturing & Production
- Embedded Software
- Testing & QA
LATEST JOBS
- Azure DevOps Engineer
- IT Helpdesk Support Engineer
- Senior SOC Analyst
- Opensource Engineer
- Application Developer (Agentic...
- Market & Liquidity Risk Busine...
- AWS DevOps Consultant - DV Cle...
- FPGA Engineer
- Sr. FPGA Engineer
- Senior FPGA Engineer
- Full Stack Java Developer - Co...
- Fiber Engineer
TOP SEARCHES
LOCATIONS
- Engineer
- Data Scientist
- Senior Data Scientist
- Head of Data Science
- Trainee Data Scientist
- Data Science Graduate
- Senior Financial Accountant
- Management Accountant
- Cost Accountant
- Civil Engineer
- Senior Civil Engineer
- Civil Design Engineer